TY - CONF AU - Stach, Christoph AU - Gritti, Clémentine AU - Mitschang, Bernhard A2 - Hung, Chih-Cheng A2 - Cerny, Tomas A2 - Petrlic, Ronald A2 - Sorge, Christoph T1 - Bringing Privacy Control Back to Citizens: DISPEL — A Distributed Privacy Management Platform for the Internet of Things T2 - Proceedings of the 35ᵗʰ ACM/SIGAPP Symposium On Applied Computing PB - ACM AD - Brno Y1 - 2020/march SP - 1272 EP - 1279 M3 - https://doi.org/10.1145/3341105.3375754 KW - privacy; attribute-based access control; IoT; authorization concept N2 - The Internet of Things (IoT) is becoming increasingly popular. It enables a variety of novel applications. Such applications require a lot of data about their users. To this end, sensors continuously monitor various aspects of daily life. Despite the indisputable benefits of IoT applications, this is a severe privacy threat. Due to the GDPR coming into force, there is a need for action on the part of IoT vendors. In this paper, we therefore introduce a Privacy by Design approach for IoT applications called DISPEL. It provides a configuration method enabling users to specify globally, which application may access what data for which purpose. Privacy protection is then applied at the earliest stage possible, i.e., directly on the IoT devices generating the data. Data transmission is protected against unauthorized access and manipulation. Evaluation results show that DISPEL fulfills the requirements towards an IoT privacy system. ER -